Slashdot Mirror


FBI Remotely Installs Spyware to Trace Bomb Threat

cnet-declan writes "There have been rumors for years about the FBI remotely installing spyware via e-mail or by exploiting an operating system vulnerability from afar — and now there's confirmation. Last month, the FBI obtained a federal court order to remotely install spyware called CIPAV (Computer and Internet Protocol Address Verifier) to find out who was behind a MySpace account linked to bomb threats sent to a high school near Olympia, Wash. News.com has posted a PDF of the FBI affidavit, which makes for interesting reading, and a summary of the CIPAV results that the FBI submitted to a magistrate judge. It seems as though CIPAV was installed via e-mail, as an article back in 2004 hinted was the case. In addition to reporting the computer's IP address, MAC address, and registry information, it also gave the FBI updates on which IP addresses the user(s) visited. But how did the FBI get the spyware activated and past anti-virus defenses? Two obvious ways are for the Feds to find and exploit their own operating system backdoors, or to compromise security vendors..."

51 of 325 comments (clear)

  1. How long will it be before ... by 140Mandak262Jamuna · · Score: 4, Insightful

    ... FBI (and some if-it-will-save-one-child-it-is-worth-it legislators) demand all the OS vendors to install backdoors so that it can come in and install whatever spyware it wants to be installed?

    --
    sed -e 's/Chuck Norris/Rajnikant/g' joke > fact
    1. Re:How long will it be before ... by ArcherB · · Score: 4, Interesting

      First they came for the library records, you did not care because you cant read

      Then they came for net access records, you did not care because you don't need privacy there ...

      Someday they will come for you, and there will be no one left to care They did have a warrant.

      --
      There is no "I disagree" mod for a reason. Flamebait, Troll, and Overrated are not substitutes.
    2. Re:How long will it be before ... by Hotawa+Hawk-eye · · Score: 3, Insightful

      Those backdoors would be the biggest targets ever for any malware authors. I'd also envision a series of lawsuits from large companies (Intel, AMD, IBM, AT&T, the big pharmaceutical manufacturers, etc.) against the OS vendors and the government as soon as somebody breaks in via the backdoors and steals confidential information. "We've spent billions of dollars researching drug X, and your backdoors allowed hackers to break in, steal all that research, and sell it to our competitors. Now tell us again why we shouldn't sue you for all you're worth, destroy your corporate headquarters, and plow salt into the earth where it once stood, as a lesson never to try this again?"

    3. Re:How long will it be before ... by Opportunist · · Score: 4, Insightful

      I only use my car for groceries. So why should I be against complete surveillance and GPS positioning of every single car? Hey, it doesn't affect me, ya know?

      I only use my credit card to pay for my phone bill. So why should I be against complete surveillance of CC payments? Hey, it doesn't affect me, ya know?

      I only...

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    4. Re:How long will it be before ... by Red+Flayer · · Score: 4, Funny

      First they came for the library records, you did not care because you cant[1] read[2a]

      Then they came for net access records, you did not care[3a] because you don't need privacy[3b] there[2b]
      [1] First they came for the apostrophe Nazis, and I did not care because I know how to use apostrophes.
      [2] Then they came for the end-of-sentence punctuation Nazis, and I did not care because I punctuate my sentences.
      [3] Then they came for tense agreement Nazis, and I did not care because I know that 'do not need privacy' (even abbreviated as don't) is present tense while 'did not care' is past tense.

      Then I realized that it matters not, because if someone can't read, they aren't going to care about net access records regardless of the privacy issues.
      --
      "Trolls they were, but filled with the evil will of their master: a fell race..." -- J.R.R. Tolkien on Olog-hai
    5. Re:How long will it be before ... by Knuckles · · Score: 3, Insightful

      The Gestapo had warrants too ...

      --
      "When I first heard Daydream Nation it quite frankly scared the living shit out of me." -- Matthew Stearns
    6. Re:How long will it be before ... by SpaceLifeForm · · Score: 3, Interesting

      And now, they don't even want to bother with that formality.

      --
      You are being MICROattacked, from various angles, in a SOFT manner.
  2. User by kevin_conaway · · Score: 2, Insightful

    But how did the FBI get the spyware activated and past anti-virus defenses? Two obvious ways are for the Feds to find and exploit their own operating system backdoors, or to compromise security vendors...

    My guess is that nothing quite so sophisticated was necessary since the user downloaded and ran an unknown attachment from an email message

  3. Hold it, hold it... by Opportunist · · Score: 3, Interesting

    ...where does it say that the guy even had any kind of AV software on his computer?

    --
    We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
  4. Heuristics and spyware by ergo98 · · Score: 5, Insightful

    Two obvious ways are for the Feds to find and exploit their own operating system backdoors, or to compromise security vendors...

    Would it even be necessary to compromise security vendors? While heuristics and malware detection has been something long promised, it is my understanding that the vast majority of security software works purely by comparing against their dictionary of known attacks. If the police have highly specialized, very limited deployment spyware, it seems that most security software wouldn't have any inkling that it's malware in the first place.

    I have no doubt that organized crime and government agencies are aware of and abusing exploits. Given that they don't blast it to the world like a giddy teenager looking for attention, no one knows what to look for.
  5. Click here for free movies! by Spudtrooper · · Score: 5, Funny

    From: spyware@fbi.gov
    Subject: Click here for free movies!
    Attachment: not_spyware.exe

    Hello! You have been selected to receive free movies at no cost to you! All you have to do is install the attached program to start downloading all the latest Hollywood hits free of charge!

    1. Re:Click here for free movies! by tehcyder · · Score: 3, Funny

      From: spyware@fbi.gov

      Subject: Click here for free movies!
      Attachment: not_spyware.exe

      Hello! You have been selected to receive free movies at no cost to you! All you have to do is install the attached program to start downloading all the latest Hollywood hits free of charge!

      Oh, FUCK.
      --
      To have a right to do a thing is not at all the same as to be right in doing it
    2. Re:Click here for free movies! by elrous0 · · Score: 2, Funny
      Headline of a future Washington Post article:

      "Our Investigation Was Going Nowhere Until We Thought of Posing as a Nigerian Prince," Says FBI Agent

      --
      SJW: Someone who has run out of real oppression, and has to fake it.
  6. Open letter reply to that kind of law by Opportunist · · Score: 4, Insightful

    "Thank you. You just made hacking a whole lot easier."

    The Germans already proposed something like that. It was retracted when they realized that it pretty much opens the door to any kind of espionage, and that this could quickly turn AGAINST them.

    No backdoor is secure. Word will get out and it will be abused. Worse yet, if you force AV and firewall manufacturers to keep that hole unplugged, you open yourself and all the businesses in your country to industrial sabotage and espionage.

    Think the feds are THAT stupid? Even if, do you think their lobbyists will allow them to?

    --
    We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    1. Re:Open letter reply to that kind of law by hpa · · Score: 5, Funny

      Think the feds are THAT stupid?
      Yes.
    2. Re:Open letter reply to that kind of law by Cro+Magnon · · Score: 2, Interesting

      Think the feds are THAT stupid? Even if, do you think their lobbyists will allow them to?


      Yes, to both! The lobbyists aren't exactly rocket scientists themselves.
      --
      Slow down, cowboy! It has been 4 hours since you last posted. You must wait another few hours.
    3. Re:Open letter reply to that kind of law by Opportunist · · Score: 2, Insightful

      Lobbyists usually don't care jack about bombs either, though. They might want to sniff through your computers to make sure you don't have files they consider theirs, but they sure as hell would not want that crap on their own machines. Imagine the feds being able to sniff through their files and finding ... teh horrorz!

      So if anything, they'll want this on the PCs of normal people, but certainly not in a system they might use themselves!

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    4. Re:Open letter reply to that kind of law by vertinox · · Score: 5, Interesting

      The Germans already proposed something like that. It was retracted when they realized that it pretty much opens the door to any kind of espionage, and that this could quickly turn AGAINST them. Its already happened to Greece's wiretapping software. Someone broke into the main cell phone company and hacked the software installed for legal wire taps to listen in on government official's cell phone. They didn't notice it until they tried to upgrade the software and realized someone had been using it.

      http://www.spectrum.ieee.org/jul07/5280/1
      --
      "I am the king of the Romans, and am superior to rules of grammar!"
      -Sigismund, Holy Roman Emperor (1368-1437)
  7. Getting past defenses? by ShaunC · · Score: 5, Insightful

    But how did the FBI get the spyware activated and past anti-virus defenses?
    Easy, they sent it to some kid on MySpace. It's a rather large assumption that he had any anti-virus defenses at all, much less that AV vendors are being complicit with the FBI trojan.

    Something seems fishy about the whole story, though. This guy was apparently savvy enough to use a proxy in Italy to send his Gmail bomb threat emails, so he was at least trying to cover his tracks... But he was dumb enough to open a random email attachment? It strikes me as more likely that the CIPAV is deployed through a browser exploit (or perhaps even "legitimately" as an ActiveX control or BHO, people will install anything).
    --
    Thanks to the War on Drugs, it's easier to buy meth than it is to buy cold medicine!
    1. Re:Getting past defenses? by Opportunist · · Score: 4, Insightful

      Using an onion router is no sign of computer knowledge. Some pal might have pointed him to The Onion Router, he saw it, went "wow, they can't track me if I got that", and that's it.

      Just because someone does something the "average Joe" cannot or does not do, doesn't mean that he knows more than said Joe. He might just have gotten some clue from a pal, without said pal telling him the whole story.

      It's simple script-kid style. Yes, some of the malware that circulates is pretty well written, but the people using it are sometimes so dumb that you wonder if they ain't better off serving fries. They're bound to be caught.

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    2. Re:Getting past defenses? by Anonymous Coward · · Score: 2, Interesting

      > Would you NOT open an attachment from an authentic fbi.gov
      > address? Criminal activity or not, ignoring that attachment
      > would be a ballsy decision.

      You really don't deserve be on the Internet. Really, you are
      a liability to others.

      Never, ever, ever open an attachment which you did not request.
      It's that easy.

  8. Where's the provision for any federal police squad by dada21 · · Score: 2, Interesting

    I keep re-reading my Constitution, and I don't see where it allows for a police power for the Federal government to go after bomb threats or any similar crime.

    Is a bomb threat considered piracy?

    Is a bomb threat considered treason?

    Is a bomb threat considered counterfeiting?

    If it isn't, there is NO Federal allocation of power to go after bomb threats, period. What the FBI is doing is not just unconstitutional, but any political leader who took an oath to uphold the Constitution is violating the only oath they took.

    It is time that the residents and citizens of the United States of America ask where the government has gotten these powers from. I know that many of the previous generation is afraid of terrorist attacks, but we are all being attacked already in having our natural rights taken away from the very government that has one major purpose: to protect us from the State who wants to take those rights away.

    It is fairly simple. The FBI has no provision in the Constitution, nor in any Amendments to said Constitution, and should just go away. Let the local State police force worry about bomb threats. If it happens from across State lines, let both State police forces work together.

  9. Re:Why are people so stupid anyway? by deftcoder · · Score: 2, Interesting

    Or, rather, you only hear about the stupid ones.

    The smart ones do not get caught.

    --
    Peace sells, but who's buying?
  10. Woot! by DRAGONWEEZEL · · Score: 2, Funny

    They think this guy really did it! I fooled 'em good!

    --
    How much is your data worth? Back it up now.
  11. Occam's razor at work by Opportunist · · Score: 4, Insightful

    We have: A teenager who used his computer to send bomb threats through myspace.

    Assumption 1: He doesn't know jack about computer security like 99% of the users out there and simply clicks everything sent to him.

    Assumption 2: The FBI keeps a hole open in Windows that only they know about.

    Assumption 3: AV vendors are forced to keep holes open, as well as firewall vendors and everyone else who could technically find it.

    Assumption 2 and 3 bear a heavy load. Assumption 2 implies that EVERY Windows OS can be remotely exploited. Now, it IS possible to reverse Windows. And since there are Windows emulators out there that can handle calls to functions most people don't even know exists, it's safe to assume that quite a few people already reversed some parts of Windows. A hole would have been found by now. More important, such a hole could easily be used against US companies when, say, China finds them and uses it to eavesdrop on confidential data. If such a hole existed, the first thing the FBI would do is make sure that no US company dealing with critical or sensitive information (nuclear, biological, you name it) uses Windows as their main operating system.

    Thus I consider it rather unlikely.

    Assumption 3 includes that every AV vendor on this planet knows about the hole/malware and keeps his mouth shut. Now, a good deal of such AV vendors sit in countries that are not the US, worse, some of those countries are economical competitors to the US. Think they'll keep silent? Or that they would include it into their software? Hardly likely.

    I'd stay with assumption 1: He was careless, clicking on everything and running no AV kit.

    --
    We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    1. Re:Occam's razor at work by dintech · · Score: 2, Funny

      implies that EVERY Windows OS can be remotely exploited.

      Who needs the FBI for this? Microsoft have been doing this all by themselves for years...

    2. Re:Occam's razor at work by Opportunist · · Score: 3, Insightful

      Still, there has to be some kind of code providing for such a signed tool. And a branch that gets never accessed is something absolutely irresistable for every reverser, especially if it looks like something that could run code on privileged levels.

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    3. Re:Occam's razor at work by PPH · · Score: 2, Informative

      Assumption 1: He doesn't know jack about computer security like 99% of the users out there and simply clicks everything sent to him.
      Most likely the case.

      However:

      Assumption 2: The FBI keeps a hole open in Windows that only they know about.
      Why is Microsoft's DoJ settlement supervised by a FISA court judge (Kathleen Kotar-Kelly). These judges are the only ones cleared to review cases where espionage techniques may be revealed and there is a need to keep such information out of the public record.

      Assumption 3 includes that every AV vendor on this planet knows about the hole/malware and keeps his mouth shut.
      AV vendors implement searches for 'well-known' virii. Suff that is widely propagated by script kiddies or phishing attacks that depend on wide distribution so that a minute response rate will be profitable. Professionally written spyware that is designed to be targeted to individuals or small groups is rarely detected. It isn't particularly difficult to tweak spyware to evade AV scans as long as you don't have to distribute millions of copies.

      Assumption 1 is probably correct but don't count on AV software to protect you if the FBI wants to peak at your system. You could lock down your system so as not to be susceptible to e-mail or web page attacks, but that cripples a Windows system to the point of being unusable for the sorts of things most MySpace users value.

      --
      Have gnu, will travel.
    4. Re:Occam's razor at work by Aeiri · · Score: 2, Interesting

      Sure, there are a lot of APIs used that are unknown to the public, there are lots of things reverse engineered, but even the most reverse engineered features have stuff in them that are unknown.

      For instance, the NTLMv2 response in NT authentication.

      NTLMv2 Specs

      Scroll down and you'll see:

      0x00000000 (unknown, but zero will work)

      This is simply the best place to put a password bypass, a flag in the authentication packet itself. If it's the right value, then just don't check the password and let the person in.

      Nobody has ever figured out what this does. All features are implemented in the NT authentication, but there are gaps that don't negatively impact anything.

  12. Re:the answer is simple by arivanov · · Score: 4, Insightful

    Neither. In the current security climate most security vendors will bend over straight away and turn a blind eye on an "authorised" Troyan. In fact at least one of the US ones is known to have done so and that was leaked to the press around 2004 (sorry forgot which one). Even further, I would not be surprised if some of them go as far as "facilitating" its installation.

    --
    Baker's Law: Misery no longer loves company. Nowadays it insists on it
    http://www.sigsegv.cx/
  13. Re:Where's the provision for any federal police sq by Attila+Dimedici · · Score: 2, Informative

    Congress does a lot of things that are not authorized in the Constitution..Social Security, Department of Education, and on and on. Many of them are "good" things. Personally, I heard a suggestion a couple of years ago that I think would be a great idea: before Congress can consider any Bill, it must contain a clause which states where in the Constitution Congress is given the authority to legislate on this particular topic. This would eliminate a lot of laws from even being considered and make it easier to determine the Constitutionality of a law. If said clause of the Constitution does not actually extend said authority, the judge can readily declare it unconstitutional and if Congress wants to authorize it based on some other clause of the Constitution, they can start over.

    --
    The truth is that all men having power ought to be mistrusted. James Madison
  14. Re:Where's the provision for any federal police sq by dada21 · · Score: 2, Insightful

    You are wrong about constitutionally protected speech when it can cause harm or mass hysteria. That is NOT protected.

    At the Federal level it surely is, regardless of what the Supreme Court wrongfully interpreted. Let us read a very simple part of the Constitution, a document written specifically to declare what the Federal Government can do, and what it is restricted from doing:

    Congress shall make no law respecting an establishment of religion, or prohibiting the free exercise thereof; or abridging the freedom of speech, or of the press; or the right of the people peaceably to assemble, and to petition the Government for a redress of grievances.

    As you can see, no law means no law. Harm, mass hysteria, are issues that have been with man since the dawn of man. They were nothing new to the Founding Fathers who knew that government uses the idea of "mass hysteria" to harm natural rights. They left those issues to the People and the Individual States.

    I'm curious how the 2nd would protect against airline hijacking though.

    Airplanes are private property. Private owners should be free to allow, or disallow, armed passengers. In fact, the United States airlines DID allow armed passengers until the Federal Government unconstitutionally prevented people from carrying their weapons on-board planes. Show me one terrorist who would dare to threaten hijacking on a plane where half the passengers are armed and trained and protecting themselves. In all the years people armed themselves on airliners, we had no issues with terrorism in the States.

  15. Why is this even on /.? by mpapet · · Score: 2, Insightful

    I know this site is a big echo chamber but the simple fact of the matter is Federal law enforcement coordinates very closely with every computer vendor that has anything of interest to them. The coordination efforts are expressly for purposes like this. I seem to recall photochop will throw an error if you try to scan U.S. currency. It's like that, only everywhere and no error messages.

    Law enforcement is very deep into every aspect of computer activity. It's been this way for more than a decade.

    The /. moral outrage rings very hollow because no one will fight for anything different.

    --
    http://www.maxineudall.com/2010/02/should-economists-be-sued-for-malpractice.html
  16. Re:Hello World by Shakrai · · Score: 2, Funny

    How hard is it to pay someone who can?

    s/pay/blackmail

    There, fixed that for you.

    --
    I want peace on earth and goodwill toward man.
    We are the United States Government! We don't do that sort of thing.
  17. The Problem by Bob9113 · · Score: 4, Interesting

    I support surveillance by law enforcement agencies. I also believe in fairly stiff penalties for breaking the law (though I would add that I feel that harsher penalties for real crimes should be balanced with reducing the breadth of behavior that the government restricts). However, I am opposed to the use of spyware on the suspect's property for such surveillance. Why this conundrum?

    The problem is that technology is getting closer to us all the time. The barrier between man and machine is becoming much narrower. And that is a good thing. At the far end of the spectrum people have long been getting artificial hearing enhancers, and now we are starting on intelligent artificial eyes and limbs. People with epilepsy are getting electronics embedded in their brains. At the nearer end of the spectrum, a large percentage of the population now carries a small computer with them everywhere (their cell phone). The man/machine split is disappearing.

    So what? Well, we have a problem developing if the government assumes that anything that does not have your genome is fair game for them to crack. Today it is the suspect's computer. This already poses a problem if the suspect is, for example, engaged in legitimate contracting for some corporation - should the government have the right to compromise the security of that corporation because one of their employees is breaking the law?

    But what of the more tightly coupled technology? Should the government be allowed to plant a bug in my hearing aid? Should they be allowed to tap the signals coming from my artificial eyes? Should they be allowed to monitor the same brain activity patterns that my seizure mitigating device monitors?

    The problem is that we are becoming more closely coupled with technology, and that is a good thing. We are the first species in history to actively engage in our own evolution. But if we cannot trust our technology, it creates a barrier to that evolutionary step. I have the right not to self-incriminate. But if a computer is part of me, where does the line get drawn?

  18. Read the real version of the story by Anonymous Coward · · Score: 5, Informative

    Declan not only ripped this story off from Wired without attribution, he got it wrong. There's no way the police could have emailed the tracking software to the kid as an attachment. Myspace doesn't allow attachments. Want to see the real story with real reporting: try the original story here: http://www.wired.com/politics/law/news/2007/07/fbi _spyware

  19. NSAKEY by bill_mcgonigle · · Score: 3, Informative

    ... FBI (and some if-it-will-save-one-child-it-is-worth-it legislators) demand all the OS vendors to install backdoors so that it can come in and install whatever spyware it wants to be installed?

    Where have you been?

    --
    My God, it's Full of Source!
    OUTSIDE_IP=$(dig +short my.ip @outsideip.net)
  20. Re:smileys.exe by TheRaven64 · · Score: 2, Funny

    If your version of file can't tell the difference between an MS-DOS executable and a Windows PE binary then you might want to consider upgrading, as it's almost certainly a good 15 years out of date.

    --
    I am TheRaven on Soylent News
  21. NSAKEY by Kadin2048 · · Score: 4, Informative
    Microsoft denied it, they said that the key's variable name being called "NSAKEY" was just an ... uh, you know ... coincidence.

    http://en.wikipedia.org/wiki/NSAKEY is a good primer.

    It was covered extensively at the time by the likes of Bruce Schneier and others, his comments said:

    Suddenly there's a flurry of press activity because someone notices that the second key in Microsoft's Crypto API in Windows NT Service Pack 5 is called "NSAKEY" in the code. Ah ha! The NSA can sign crypto suites. They can use this ability to drop a Trojaned crypto suite into your computers. Or so the conspiracy theory goes.

    I don't buy it.

    First, if the NSA wanted to compromise Microsoft's Crypto API, it would be much easier to either 1) convince MS to tell them the secret key for MS's signature key, 2) get MS to sign an NSA-compromised module, or 3) install a module other than Crypto API to break the encryption (no other modules need signatures). It's always easier to break good encryption by attacking the random number generator than it is to brute-force the key.

    Second, NSA doesn't need a key to compromise security in Windows. Programs like Back Orifice can do it without any keys. Attacking the Crypto API still requires that the victim run an executable (even a Word macro) on his computer. If you can convince a victim to run an untrusted macro, there are a zillion smarter ways to compromise security.

    Third, why in the world would anyone call a secret NSA key "NSAKEY"? Lots of people have access to source code within Microsoft; a conspiracy like this would only be known by a few people. Anyone with a debugger could have found this "NSAKEY." If this is a covert mechanism, it's not very covert.
    I think the jury is still out on exactly what was really going on; if it was an NSA backdoor, it was a pretty boneheaded one. Alternately, if it was just Microsoft being redundant, then it shows that they didn't plan very well and don't seem to understand security very well. Given the choice between the two, I think boneheadedness on MS's part is more likely.
    --
    "Ladies and gentlemen, my killbot features Lotus Notes and a machine gun. It is the finest available."
  22. Happening right now. by Anonymous Coward · · Score: 3, Interesting

    Too much info has been released and I can explain what is occurring right now. This is not speculation.

    - E-mail account made at a foreign e-mail hosting site that has an extremely terse address so as not to be hit by spambots (i.e. 4433dakjikk83726jj@somewhere.org)
    - E-mails are sent from a stolen laptop through a public wireless access point that are copycats of this crime to illicit the same FBI response.
    - E-mails are then checked each day from different public access points each day using a different MAC address at each access point. [The only e-mail that should be coming into this account would be the one from the FBI. Probably easy to verify by checking DNS records of the e-mails originating IP or IP block.]
    - E-mail is received and copied to disk.
    - Laptop is destroyed.
    - CD with e-mail is then analyzed on a Linux/Unix machine that has no internet connection.
    - Backdoor/exploit vector is discovered and used for "other" purposes.

  23. The warrant isn't really the point. by camperdave · · Score: 5, Insightful

    The warrant isn't really the point. The point is that they have the tech to get past firewalls and antivirus software, and can plant spyware on your machine. This time it was legal, because the FBI got the warrant. But what about the CIA/NSA/RIAA using the same tech to spy on you? Some government agencies don't need warrants.

    --
    When our name is on the back of your car, we're behind you all the way!
    1. Re:The warrant isn't really the point. by erroneus · · Score: 5, Insightful

      The bigger problem isn't only Government bodies or even the RIAA (who would have to disclose their methods of evidence collection as a means of validating the evidence). If they can do it, ultimately anyone can do it.

      There is no magic at play here. If it's a secret, someone can learn it. If it's a method, someone can learn it. If it can be done by one, it can be done by all and whether or not you trust your government or your legal system is almost irrelevant to the larger point. If there exists that serious of a chink in your armor, SOMEONE will exploit it and it may not always be for the right reasons or by the right people.

  24. Re:Where's the provision for any federal police sq by giafly · · Score: 2, Insightful

    Show me one terrorist who would dare to threaten hijacking on a plane where half the passengers are armed and trained and protecting themselves.
    • You have apparantly never heard of suicide bombers?
    • Also who needs real terrorists if half the passengers are trigger-happy amateurs? Just 'phone in a hoax and hope they panic.
    --
    Reduce, reuse, cycle
  25. Grey-market exploits by athloi · · Score: 2, Interesting

    The answer is right in front of you. Governments and spy shops pay for exploits before they're made public, so they can use them to enter your machine as they need to. In this case, we don't know how CIPAV was delivered, but it might be as simple as an undiscovered exploit in Outlook or a browser-based email system. While none of us trust government, I equally don't trust my fellow citizens, so the "ethics" of this point are moot.

  26. Re:the answer is simple by pe1chl · · Score: 4, Insightful

    But what if you (as any sensible person would do) simply block anything that is executable from being received via mail?

  27. Updated by PooseCat · · Score: 2, Interesting
    --
    ^..^
  28. Real or just FBI PR? by EmbeddedJanitor · · Score: 2, Insightful

    After Sept 11. the FBI etc have PR issues trying to convince the world that they are on the ball and protecting Joe Citizen. These sorts of statement are not necessarily true. They could just be "feel good" measures like making you take your shoes off at airports.

    --
    Engineering is the art of compromise.
  29. I'm kind of new here by SIIHP · · Score: 5, Insightful

    But posts like this really irk me.

    What exactly do you want?They got a warrant. Isn't that kind of oversight what we want? I don't understand why you think making a comparison to the Gestapo (and did they really have warrants?) adds a single thing to the conversation.

    Please tell me what your solution is, so I can put your comment in some kind of context. I've seen it and its like from several other posters, but not a single one of them goes on to make a coherent argument after making it, and neither did you.

    The FBI has a job, in this case it seems a job that we'd all like them to be proficient at, that of preventing bombings. They pursued evidence through the correct channels, got a warrant, set up an operation, and did their jobs. In light of that, doesn't the "Gestapo" comment seem a bit reactionary and irrational?

    So what the hell is with the specious Gestapo comparison? Do you think someone's rights were violated somehow, or the FBI overstepped their authority, or what exactly? Or is it vogue here to toss out inflammatory comments for no reason other than to provoke a reaction? I thought that's what the "troll" mod was for?

    Lastly, the Gestapo also pandered to the fears and insecurities of the populace, so I'd be careful throwing around such comparisons if I were you.

    --
    I only go to buffets for the unlimited soft serve.
    1. Re:I'm kind of new here by toiletsalmon · · Score: 2, Insightful

      "What exactly do you want?"

      You know what I want? I want to be able to TRUST that the executive branch of the government (law enforcement included) really has what's best for the country in mind, but I'm just not feeling it.

      The executive branch of our government has recently, been found guilty of large scale domestic spying "for the greater good", torture, and any number of other egregious offenses. Of course, it's up to some interpretation I guess, but I say they're blatantly illegal offenses at worst and contrary to the spirit of our laws in the very least.

      If they're so willing to throw aside our laws to accomplish what they want in extreme cases, exactly where do they draw the line? Torture is OK, but what about murder? Installing spyware is OK to get the data you need, but what about fabricating data? When are we going to reel these guys in, and at what eventual cost?

      I don't care if they had a warrant in this particular instance. I don't care if the guy they were going after was just a petty crook, truly a terrorist, or even a pedophile. What I DO care about is the fact that we've already seen that the legislative branch is more than willing to re-write portions of our law to make this sort of "sneaky" behavior perfectly legal, for the sake of "safety" and "security". I'm not so sure that it's a good thing that it's getting harder and harder to tell the difference between the tactics used by the "good guys" and those employed by the "bad guys". I thought law enforcement was supposed to be taking the high ground and fighting fair. Isn't that part of what being a "good guy" is all about? Morals and integrity and whatnot?

      And another thing, even if all this stuff is "legal", I don't like seeing them practice these strong-arm tactics on even the real bad guys. It makes me nervous, because I've learned first hand that, regardless of what's "legal" or "right", when you're mistakenly on the wrong end of one of these actions, knowing that the courts MIGHT eventually straighten it out won't make you feel any better when you're sitting around in jail (or god forbid, in a coffin).

      "Oops. Sorry. We weren't supposed to do that..."

      Basically, I want the good guys to start acting like good guys and cut out all the god-damned shenanigans. Stooping to the crooks level will, and is, taking us down a path I don't really think we want to be on.

  30. Re:the answer is simple by ozric99 · · Score: 5, Funny

    Even then, the Acrobat process would need write-access to system files. On a decently managed system, it hasn't.
    From the summary:
    A MySpace account linked to bomb threats sent to a high school.

    Chances of this system being secure, updated, well-managed? 0
    Chances of this system being a Gateway laptop that takes 10 minutes to boot, loads 5 IM apps on startup, has 4 different IE toolbars, and constantly warns that the Norton Antivirus subscription lapsed 16 months ago? Our survey says yes!
  31. Re:the answer is simple by ehrichweiss · · Score: 2, Interesting

    Ever heard of a rootkit? Those are installed every day without a single peep from an up-to-date AV scanner. Hell, I've got a book on creating them right now that has an example that has managed to bypass Avira and AVG. And that's just example code.

    --
    0x09F911029D74E35BD84156C5635688C0